Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
422 commits
Select commit Hold shift + click to select a range
c07c9e4
Merge pull request #2678 from lidge-jun/codex/prompt-layers-route
lidge-jun Aug 26, 2026
a87083d
Merge pull request #2679 from lidge-jun/codex/prompt-layers-shell
lidge-jun Aug 26, 2026
bfcb7c2
Merge pull request #2680 from lidge-jun/codex/prompt-layers-authoring
lidge-jun Aug 26, 2026
186b8ef
Merge pull request #2681 from lidge-jun/codex/prompt-layers-realtext
lidge-jun Aug 26, 2026
94b5d94
Merge pull request #2682 from lidge-jun/codex/prompt-layers-docs
lidge-jun Aug 26, 2026
9e746d8
Merge pull request #2685 from lidge-jun/codex/restart-codex-npm-wrapper
lidge-jun Aug 26, 2026
90b7ed4
Merge pull request #2683 from lidge-jun/codex/session-lane-reconnect
lidge-jun Aug 26, 2026
6c70924
fix(openai-chat): compose shared properties and leave data keywords a…
Aug 26, 2026
8412fe1
Merge pull request #2677 from lidge-jun/codex/moonshot-ref-sibling-sc…
lidge-jun Aug 26, 2026
4c8814e
feat(providers): seed glm-5.3-flash across the GLM-5.2 catalogs
Aug 26, 2026
792ca96
ci: re-trigger Cross-platform CI after a runner startup_failure
Aug 26, 2026
3289312
fix(providers): glm-5.3-flash is a VLM, and drop Ox Alpha entirely
Aug 26, 2026
5d0a97b
Merge pull request #2687 from lidge-jun/codex/glm-53-flash-preseed
lidge-jun Aug 26, 2026
618809d
devlog(260827): review dev against main, and plan the base variants
Aug 26, 2026
83cf732
fix(cursor): survive a desktop executor that never reads stdin
Aug 26, 2026
866073e
test(providers): move two stale allowlist counts to what the registry…
Aug 26, 2026
5916df1
fix(server): stop a chmod from fencing the data plane behind 503
Aug 26, 2026
d66252e
fix(codex): require a dashboard session to rewrite the prompt stack
Aug 26, 2026
583f5a2
fix(codex): keep a BOM at byte 0, and roll back a refused write
Aug 26, 2026
59d9bc9
fix: stop deleting reused branches, and finish the glm-5.3-flash corr…
Aug 26, 2026
b0e893e
test(ci): import the cleanup helper without a lint suppression
Aug 26, 2026
f25dab8
test(providers): move two more assertions that pinned the incomplete …
Aug 26, 2026
bbfdd65
feat(codex): show the commit-attribution layer, and stop rows claimin…
Aug 26, 2026
f0c14b6
Merge pull request #2695 from lidge-jun/codex/desktop-exec-epipe
lidge-jun Aug 26, 2026
942cb04
Merge pull request #2689 from lidge-jun/codex/pkgtree-503-false-positive
lidge-jun Aug 26, 2026
9f7d709
Merge pull request #2691 from lidge-jun/codex/branch-cleanup-sha-guard
lidge-jun Aug 26, 2026
ee182a1
Merge pull request #2692 from lidge-jun/codex/git-attribution-layer
lidge-jun Aug 26, 2026
b715985
feat(codex): base-prompt variants, with a default that cannot be edited
Aug 26, 2026
71f1299
feat(gui): a real switch on base, and a swipeable variant picker
Aug 26, 2026
18b9393
test(gui): the base position label has no French to write
Aug 26, 2026
06e8e8a
docs(pr): screenshots of the base switch and the variant picker
Aug 26, 2026
a3f5335
docs(devlog): record the remote gate, including the locale check it c…
Aug 26, 2026
924efc9
Merge pull request #2707 from lidge-jun/codex/base-prompt-variants
lidge-jun Aug 26, 2026
183286d
docs: base prompt variants and commit attribution, in five locales
Aug 26, 2026
ab63ded
Merge pull request #2708 from lidge-jun/codex/base-variant-docs
lidge-jun Aug 26, 2026
094a25c
feat(gui): UX polish for the prompt-layer panel
Aug 27, 2026
e92f6c1
docs(pr): UX polish screenshots — panel with left accents and dialog …
Aug 27, 2026
87ce20c
test(gui): the dot indicator renders and follows the ring position
Aug 27, 2026
9b838d0
Merge pull request #2719 from lidge-jun/codex/prompt-ux-polish
lidge-jun Aug 27, 2026
c3ef630
docs(devlog): intake matrix and lane roadmap for the 260827 bug-PR me…
lidge-jun Aug 27, 2026
d1c3988
docs(devlog): fold A-gate audit corrections into the merge-round plan
lidge-jun Aug 27, 2026
90ef53f
docs(devlog): operative execution order for the merge round
lidge-jun Aug 27, 2026
2a9c18d
Merge pull request #2672 from Ingwannu/ingw/fix-responses-forward-sys…
lidge-jun Aug 27, 2026
e3b136f
Merge pull request #2674 from Ingwannu/ingw/fix-posit-responses-conti…
lidge-jun Aug 27, 2026
17aadf8
Merge pull request #2671 from DevonGithub/codex/muse-spark-vision
lidge-jun Aug 27, 2026
4a4df12
test(catalog): pin Muse image input against a text-only discovered row
lidge-jun Aug 27, 2026
2c85dd4
Merge pull request #2684 from Michael-Z-Freeman/fix/azure-model-route…
lidge-jun Aug 27, 2026
36ff16e
docs(devlog): fold audit round 2 into the merge-round plan
lidge-jun Aug 27, 2026
2feffbd
Merge pull request #2720 from lidge-jun/codex/l1-merge-round-260827
lidge-jun Aug 27, 2026
fefeb05
fix(responses): backfill missing status for strict decoders
lidge-jun Aug 27, 2026
e1e6ec0
fix(command-code): add reasoning effort ladders for three live models
lidge-jun Aug 27, 2026
7a28fa5
fix(xai): normalize Responses root tool schemas
olddonkey Aug 26, 2026
e2ca660
fix(xai): preserve oneOf exclusivity and bound schema flattening
olddonkey Aug 26, 2026
6877f64
fix(responses): treat a queued response as in_progress, not completed
lidge-jun Aug 27, 2026
7d49790
docs(devlog): record the status/created_at asymmetry found at the L3 …
lidge-jun Aug 27, 2026
45c3d31
fix(command-code): keep Ox Alpha out of the regenerated catalog fixture
lidge-jun Aug 27, 2026
8af9ff2
docs(responses): repair the backfill docblock left broken by the crea…
lidge-jun Aug 27, 2026
ad8ab4f
fix(command-code): stop claiming the effort ladders self-correct
lidge-jun Aug 27, 2026
b64de51
docs(devlog): record the L3 audit findings and dispositions
lidge-jun Aug 27, 2026
da1e8af
test(command-code): pin the broken profile-refresh path
lidge-jun Aug 27, 2026
0209234
fix(kiro): send Kiro's service profile for AWS Builder ID accounts
Aug 27, 2026
1241021
fix(kiro): key the Builder ID wire path off the resolver's own verdict
Aug 27, 2026
64c6d64
Merge pull request #2721 from lidge-jun/codex/l3-cherry-picks-260827
lidge-jun Aug 27, 2026
307d2e0
docs(devlog): record the L1 lane outcome
lidge-jun Aug 27, 2026
0f10e57
docs(devlog): point the plan's verification section at the real test …
Aug 27, 2026
cb9bb9b
fix(responses): bridge bare code-mode helper calls through exec
lidge-jun Aug 27, 2026
56be8f6
docs(devlog): plan the Kiro Responses text-control guard fix
lidge-jun Aug 27, 2026
524a294
test(kiro): pin non-structured Responses text controls
lidge-jun Aug 27, 2026
a0d1ebb
fix(kiro): reject only genuine structured output
lidge-jun Aug 27, 2026
ce52a00
docs(kiro): document Responses text control handling
lidge-jun Aug 27, 2026
314d41d
test(kiro): make the wire-absence assertion non-vacuous
lidge-jun Aug 27, 2026
cebe005
Merge pull request #2724 from lidge-jun/codex/l2-2663-code-mode-exec
lidge-jun Aug 27, 2026
669efd5
test(xai): pin the additionalProperties composition boundary
olddonkey Aug 27, 2026
6769db6
docs(devlog): record the L2 lane outcome and audit
lidge-jun Aug 27, 2026
3d986ef
Merge pull request #2690 from olddonkey/codex/fix-xai-responses-root-…
lidge-jun Aug 27, 2026
4c5adb2
docs(devlog): record the L4 lane outcome
lidge-jun Aug 27, 2026
77e0370
Merge pull request #2727 from lidge-jun/codex/l4-round-260827
lidge-jun Aug 27, 2026
3727207
docs(devlog): close the Kiro text-control unit
lidge-jun Aug 27, 2026
729f01e
docs(devlog): close out the 260827 bug-PR merge round
lidge-jun Aug 27, 2026
41fcc9f
Merge pull request #2728 from lidge-jun/codex/round-closeout-260827
lidge-jun Aug 27, 2026
70159d9
Merge pull request #2722 from lidge-jun/codex/kiro-builder-id-profile
lidge-jun Aug 27, 2026
7547c89
Merge pull request #2725 from lidge-jun/codex/kiro-text-control-guard
lidge-jun Aug 27, 2026
005c0dc
fix(scripts): restart proxy without setsid on macOS
lidge-jun Aug 27, 2026
056d299
Merge pull request #2735 from lidge-jun/codex/fix-ocx-restart-macos
lidge-jun Aug 27, 2026
4188f5a
docs(devlog): close macOS restart repair
lidge-jun Aug 27, 2026
06fa680
Merge pull request #2736 from lidge-jun/codex/close-ocx-restart-macos
lidge-jun Aug 27, 2026
b49c4dc
fix(server): keep source checkout live during edits
lidge-jun Aug 27, 2026
17577c9
Merge pull request #2737 from lidge-jun/codex/source-checkout-integrity
lidge-jun Aug 27, 2026
afe22b2
docs(devlog): hardening inventory and remediation roadmap for dev
lidge-jun Aug 27, 2026
9919438
docs(devlog): record the launcher-recovery flake as a real readiness …
lidge-jun Aug 27, 2026
e4a85d1
fix(release): stop dev from carrying a version behind its own releases
lidge-jun Aug 27, 2026
5dfee1a
Merge pull request #2738 from lidge-jun/codex/dev-hardening-inventory
lidge-jun Aug 27, 2026
a223a2b
fix(release): make the version-line guard bite on release commits and…
lidge-jun Aug 27, 2026
7297bc8
ci: fetch tags without cloning full history for the version-line check
lidge-jun Aug 27, 2026
ca3b379
Merge pull request #2739 from lidge-jun/codex/dev-version-line
lidge-jun Aug 27, 2026
7c87039
test(ci): pin fetch-tags on the jobs that run the suite
lidge-jun Aug 27, 2026
0343569
docs(devlog): correct the wp3 failover-identity severity from a secon…
lidge-jun Aug 27, 2026
b8ad97a
ci: fetch tags on the Windows suite leg too
lidge-jun Aug 27, 2026
a57b962
Merge pull request #2743 from lidge-jun/codex/pin-ci-fetch-tags
lidge-jun Aug 27, 2026
2c123e8
docs: stop shipping locale pages that state the opposite of the code
lidge-jun Aug 27, 2026
2fc97f7
docs: name the current native-exec control in the remaining four locales
lidge-jun Aug 27, 2026
4f81880
test: harden the README asset check against two false verdicts
lidge-jun Aug 27, 2026
95314c1
docs: finish the adapter-count sweep the first pass left half-done
lidge-jun Aug 27, 2026
802f04a
Merge pull request #2746 from lidge-jun/codex/locale-docs-contradictions
lidge-jun Aug 27, 2026
e6661f2
fix(gui): make doctor:gui agree with CI instead of being bypassed
lidge-jun Aug 27, 2026
9542b26
test(gui): lock the exhaustive-deps suppression against going inert
lidge-jun Aug 27, 2026
5000321
Merge pull request #2749 from lidge-jun/codex/doctor-gui-agrees-with-ci
lidge-jun Aug 27, 2026
af479e0
test(core): lock the two invariants AGENTS.md claims are enforced
lidge-jun Aug 27, 2026
9493095
docs(agents): name the activation enforcement, and stop tripping the …
lidge-jun Aug 27, 2026
8be960f
test(core): extend the activation scan through the return, not just t…
lidge-jun Aug 27, 2026
2a72cc0
Merge pull request #2751 from lidge-jun/codex/lock-activation-invariants
lidge-jun Aug 27, 2026
a195ba6
docs(devlog): close the dev hardening unit with a promotion-readiness…
lidge-jun Aug 27, 2026
c457c70
Merge pull request #2752 from lidge-jun/codex/dev-hardening-readiness
lidge-jun Aug 27, 2026
3bfea61
fix(kiro): enable the code-mode catalog nudge so ALL_TOOLS discovery …
Aug 27, 2026
8f702b2
fix(kiro): reserve catalog room for the code-mode execution path
Aug 27, 2026
a4d9fb8
docs(devlog): record wp2 check evidence and the live parallel-delegat…
Aug 27, 2026
d44c406
test(kiro): assert the byte budget holds when exec is reserved
Aug 27, 2026
9421938
docs(devlog): record the remote shard 4/4 triage
Aug 27, 2026
eeb7740
Merge pull request #2750 from lidge-jun/codex/kiro-subagent-delegatio…
lidge-jun Aug 27, 2026
bb31c26
docs(devlog): record that dev advanced past the sha the readiness sta…
lidge-jun Aug 27, 2026
7c333f3
Merge pull request #2754 from lidge-jun/codex/readiness-sha-addendum
lidge-jun Aug 27, 2026
f7f07fd
docs(devlog): plan the dev -> preview -> main release train
lidge-jun Aug 27, 2026
7ca954f
Merge pull request #2755 from lidge-jun/codex/release-train-roadmap
lidge-jun Aug 27, 2026
e25b653
merge dev into main for the v2.34.0 release
lidge-jun Aug 27, 2026
80fff9a
Merge pull request #2760 from lidge-jun/codex/promote-main-2340
lidge-jun Aug 27, 2026
539d18d
fix(ci): grant workflows write permission to fork sync and dev backmerge
yansigit Aug 27, 2026
98a5e27
Merge pull request #96 from yansigit/codex/fix-fork-sync-workflows-pe…
yansigit Aug 27, 2026
f2ba654
fix(ci): use valid actions write permission for workflow updates in f…
yansigit Aug 27, 2026
8baf42b
Merge pull request #97 from yansigit/codex/fix-actions-write-permission
yansigit Aug 27, 2026
3cfdb08
feat(config): add subagentCandidates schema and candidate resolution …
yansigit Aug 27, 2026
d7ca156
feat(subagent): overwrite spawn models with configured candidates and…
yansigit Aug 27, 2026
3b28b48
fix(subagent): broaden provider 5xx cooldown matching and review cleanup
yansigit Aug 27, 2026
1f6fe89
feat(effort): auto-sanitize reasoning effort for effortless models
yansigit Aug 27, 2026
37228e4
feat(guidance): add subagent role override and code-mode isolate guid…
yansigit Aug 27, 2026
c49207c
fix(guidance): preserve literal backslashes in code-mode escaping gui…
yansigit Aug 27, 2026
10c4d62
docs(plan): add subagent-candidates-failover implementation plan
yansigit Aug 27, 2026
9fa756d
feat(ci): activate automatic npm package publishing for dev branch
yansigit Aug 27, 2026
febe905
test(ci): update release workflow channel guard assertion for dev branch
yansigit Aug 27, 2026
a898584
Merge pull request #100 from yansigit/codex/activate-dev-npm-publish
yansigit Aug 27, 2026
13e7279
Merge pull request #101 from yansigit/codex/subagent-driver-candidate…
yansigit Aug 27, 2026
95969a2
fix(cursor): resolve empty exec output loops, replay repetition, and …
yansigit Aug 27, 2026
f3b342c
Merge pull request #102 from yansigit/codex/fix-cursor-replay-and-exe…
yansigit Aug 27, 2026
b2439d6
docs: add implementation plan for Google AI Studio web status and re-…
yansigit Aug 27, 2026
745d97a
fix(google): detect upstream HTML login redirect and isolate aistudio…
yansigit Aug 27, 2026
6aea452
fix(cli): do not open bridge web page after native or token login
yansigit Aug 27, 2026
1d4c5ea
fix(server): poll aistudio status via http in bridge html instead of …
yansigit Aug 27, 2026
d03ab9b
fix(server): support chrome-extension CORS preflight and dynamic port…
yansigit Aug 27, 2026
cbd78f7
fix(server): cleanly apply aistudio CORS to all branches and assert d…
yansigit Aug 27, 2026
b51ac16
feat(server): expose live aistudio status, test probe, and native re-…
yansigit Aug 27, 2026
8d474f4
feat(gui): accurate aistudio status in catalog and re-auth action in …
yansigit Aug 27, 2026
b42c5df
fix(relay): strip forbidden headers and omit body on GET in browser r…
yansigit Aug 27, 2026
0a9be9c
docs: define macOS direct-session AI Studio architecture
yansigit Aug 27, 2026
d914e54
docs: plan macos direct-session aistudio implementation
yansigit Aug 27, 2026
487f06e
fix(aistudio): checkpoint concurrent relay hardening
yansigit Aug 27, 2026
2159cd7
refactor(aistudio): centralize direct session credentials
yansigit Aug 27, 2026
c7bfc47
fix(aistudio): guard malformed credential values
yansigit Aug 27, 2026
5455bb2
feat(aistudio): await native macos authentication
yansigit Aug 27, 2026
20c47fc
feat(aistudio): await native macos authentication
yansigit Aug 27, 2026
c5931bd
refactor(aistudio): retire browser inference relay
yansigit Aug 27, 2026
5ea2701
docs(aistudio): document native direct-session workflow
yansigit Aug 27, 2026
576db59
fix(usage): persist non-PII OAuth account ID and fix multi-account us…
yansigit Aug 27, 2026
b8010d7
Merge pull request #103 from yansigit/codex/fix-oauth-account-usage-a…
yansigit Aug 27, 2026
b3b62fa
Merge pull request #104 from yansigit/codex/fix-aistudio-web-status-r…
yansigit Aug 27, 2026
8704208
fix(ci): ensure hotspot sync branch is refreshed and cursor fallback …
yansigit Aug 27, 2026
e29a0f6
Merge pull request #105 from yansigit/codex/fix-fork-sync-stale-and-c…
yansigit Aug 27, 2026
903d4ab
fix(cursor): send Bearer auth for api2.cursor.sh webhook
yansigit Aug 28, 2026
fd7f2e2
Merge remote-tracking branch 'origin/dev' into codex/fix-cursor-webho…
yansigit Aug 28, 2026
e8907b6
Merge pull request #106 from yansigit/codex/fix-cursor-webhook-bearer…
yansigit Aug 28, 2026
dac549d
fix(jules): auto-nudge stalled sync-hotspot feedback loop
yansigit Aug 28, 2026
6451b03
fix(jules): auto-nudge stalled sync-hotspot feedback loop (#107)
yansigit Aug 28, 2026
596916c
docs(sync): require sticky cursor progress checklist on hotspot PRs
yansigit Aug 28, 2026
be90d42
Merge remote-tracking branch 'origin/dev' into codex/cursor-progress-ux
yansigit Aug 28, 2026
b0293b7
sync: merge upstream v2.34.0 (80fff9a) into dev
cursoragent Aug 28, 2026
e864fb6
Merge pull request #109 from yansigit/codex/cursor-progress-ux
yansigit Aug 28, 2026
e077769
Merge remote-tracking branch 'origin/dev' into sync/upstream-v2.34.0-…
yansigit Aug 28, 2026
97fa847
fix(codex): display 5-hour rolling limit alongside weekly limit on Op…
yansigit Aug 28, 2026
9b2f56a
test(codex): add regression tests for 5-hour quota parsing and preser…
yansigit Aug 28, 2026
393d269
fix(gui): include missing dependencies in ProviderOverview callbacks
yansigit Aug 28, 2026
213edb9
test: sync loopback upgrade and parity endpoints to match latest runtime
yansigit Aug 28, 2026
fd82b0e
test(aistudio): skip native macos auth status test on non-darwin plat…
yansigit Aug 28, 2026
317d7be
test: align locale allowlists and deprecated AI studio relay test
yansigit Aug 28, 2026
55ee564
test(subagents): use client error for non-blocking terminal test
yansigit Aug 28, 2026
f62f970
Merge pull request #111 from yansigit/codex/openai-quota-bars
yansigit Aug 28, 2026
365d325
fix(sync): babysit hotspot PRs until mergeable and keep cursor superv…
yansigit Aug 28, 2026
7990da3
Merge pull request #110 from yansigit/codex/sync-babysitter
yansigit Aug 28, 2026
7b8637e
merge dev into upstream sync branch
yansigit Aug 28, 2026
d931c79
fix: reconcile quota DTO aliases after sync merge
yansigit Aug 28, 2026
0c6c5af
fix: restore fork behavior after upstream sync merge
yansigit Aug 28, 2026
5f21b14
fix(gui): avoid new compiler suppression in models page
yansigit Aug 28, 2026
af9356e
fix: align sync contracts with restored catalog behavior
yansigit Aug 28, 2026
c8f020b
fix(stability): add Codex WS transport controls, delta coalescing, an…
yansigit Aug 28, 2026
3731b60
fix: preserve fork config and quota contracts
yansigit Aug 28, 2026
988c060
fix(cursor): preserve neutral external tool replay
yansigit Aug 28, 2026
4f29925
docs(spec): add autonomous issue remediation pipeline design
yansigit Aug 28, 2026
3d76a9d
feat: add telemetry fingerprint ledger
yansigit Aug 28, 2026
b213c9b
feat(maintenance): add autonomous merge evidence and auto-merge to dev
yansigit Aug 28, 2026
df74f17
fix(ci): supervise sync PR checks and refresh progress
yansigit Aug 28, 2026
2bc07b9
fix(cursor): restore tool schemas and safe remint recovery
yansigit Aug 28, 2026
6aa5ab9
fix(responses): restore TLS transport and gate test auth seam
yansigit Aug 28, 2026
41bbb81
feat: add authorized telemetry issue dispatcher
yansigit Aug 28, 2026
48651b5
feat: intercept runtime failures for autonomous remediation
yansigit Aug 28, 2026
e1fd7ce
fix(cursor): persist recovered desktop thread owner
yansigit Aug 28, 2026
eeacc29
docs(plan): add autonomous issue remediation pipeline implementation …
yansigit Aug 28, 2026
b78ef20
Merge pull request #112 from yansigit/codex/autonomous-issue-remediat…
yansigit Aug 28, 2026
c30f313
Merge remote-tracking branch 'origin/dev' into sync/upstream-v2.34.0-…
Aug 28, 2026
03482c9
fix(subagent): restore candidate resolution and failure tracking
yansigit Aug 28, 2026
2cde5f7
fix(cursor): restore model and runtime error normalization
yansigit Aug 28, 2026
ea3658c
fix: restore hosted tool normalization and subscription credits
yansigit Aug 28, 2026
b6090c3
Merge remote-tracking branch 'origin/sync/upstream-v2.34.0-80fff9a' i…
yansigit Aug 28, 2026
3d9816c
fix cursor background shell process trees
yansigit Aug 28, 2026
b90aeef
fix(ci): distinguish pending sync baselines
yansigit Aug 28, 2026
b79cfe4
fix cursor process tree escalation
yansigit Aug 28, 2026
9f693d3
test(ci): cover generated sync baseline decision
yansigit Aug 28, 2026
b757318
fix cursor process group liveness escalation
yansigit Aug 28, 2026
b9c2295
fix cursor process group liveness errors
yansigit Aug 28, 2026
c4e3385
fix cursor cleanup fallback escalation
yansigit Aug 28, 2026
0bdb321
test(responses): align abort-race with delta coalescing and bound cur…
yansigit Aug 28, 2026
26656eb
fix(cursor): terminate background process trees (#114)
yansigit Aug 28, 2026
0add7ff
Merge remote-tracking branch 'origin/dev' into sync/upstream-v2.34.0-…
Aug 28, 2026
e662399
test(responses): use valid runTurn event phases
yansigit Aug 28, 2026
e53edcb
Merge pull request #115 from yansigit/codex/fix-abort-event-phase
yansigit Aug 28, 2026
78dd352
Merge remote-tracking branch 'origin/dev' into sync/upstream-v2.34.0-…
Aug 28, 2026
3ff726b
fix(ci): distinguish pending sync baselines
yansigit Aug 28, 2026
dc1d32a
test(ci): cover generated sync baseline decision
yansigit Aug 28, 2026
58e799b
Merge pull request #113 from yansigit/codex/fix-sync-baseline-gate
yansigit Aug 28, 2026
ec85232
Merge remote-tracking branch 'origin/dev' into sync/upstream-v2.34.0-…
Aug 28, 2026
3825d6e
Merge remote-tracking branch 'origin/dev' into codex/resolve-sync-108
yansigit Aug 28, 2026
432b8f5
Merge remote-tracking branch 'origin/sync/upstream-v2.34.0-80fff9a' i…
yansigit Aug 28, 2026
b313261
fix(gui): preserve creditsUsd contract without synthesizing duplicate…
yansigit Aug 28, 2026
a8f110e
Merge remote-tracking branch 'origin/sync/upstream-v2.34.0-80fff9a' i…
yansigit Aug 28, 2026
1b7212a
fix(codex): default upstream responses to HTTP SSE
yansigit Aug 28, 2026
a33d82d
docs: clarify Codex WebSocket opt-in
yansigit Aug 28, 2026
4a066b2
fix: wire Codex WebSocket controls safely
yansigit Aug 28, 2026
6d76a21
fix(management): normalize wsUpstream null on provider create and use…
yansigit Aug 28, 2026
05aa890
Merge pull request #116 from yansigit/codex/ws-default-http-sse
yansigit Aug 28, 2026
cb7b78e
fix(cursor): restore cursorBlobServeIntegrityOk diagnostic export
yansigit Aug 28, 2026
571a904
ci: trigger PR #108 verification
yansigit Aug 28, 2026
3ef89a7
Merge remote-tracking branch 'origin/dev' into codex/resolve-sync-108
yansigit Aug 28, 2026
29bd403
fix(ci): wake PR enforcement after aggregate CI
yansigit Aug 28, 2026
e740804
test(ci): cover workflow run trust boundaries
yansigit Aug 28, 2026
5930ad0
Merge pull request #117 from yansigit/codex/fix-sync-workflow-wakeup
yansigit Aug 28, 2026
f099794
Merge remote-tracking branch 'origin/dev' into sync/upstream-v2.34.0-…
Aug 28, 2026
d38cbfd
Merge pull request #108 from yansigit/sync/upstream-v2.34.0-80fff9a
yansigit Aug 28, 2026
7e80311
Merge commit 'f6a1075272841aab2e6c3769a9d432f9bf471441' into codex/ba…
yansigit Aug 28, 2026
6be07fa
Merge pull request #119 from yansigit/codex/backmerge-main-supervisor
yansigit Aug 28, 2026
62eb1c6
fix: check native login response status before body
yansigit Aug 28, 2026
0b1e14c
fix: render nested native login errors safely
yansigit Aug 28, 2026
2ea6e77
test: preserve Bun runtime in update fixture
yansigit Aug 28, 2026
3aac700
test: enforce native login status check ordering
yansigit Aug 28, 2026
9350b90
Merge pull request #120 from yansigit/codex/fix-promotion-react-doctor
yansigit Aug 28, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
15 changes: 15 additions & 0 deletions .cursor/skills/opencodex-fork-sync/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,6 +69,21 @@ fast-forward of `upstream/main`; `vendor/dev` remains an exact fast-forward of
branch. The issue notifier is selected by `FORK_SYNC_NOTIFIERS=github-issue`;
the Cursor coordinator is selected by `FORK_SYNC_COORDINATORS=cursor-webhook`.

Keep the PR readable while the automation works. Maintain exactly one sticky
progress comment with marker `<!-- cursor-sync-progress -->` and one matching
PR-body section between `<!-- cursor-sync-progress:start -->` and
`<!-- cursor-sync-progress:end -->`. Update both in place after every push,
never post a new comment. Inside each, render a 4-line checklist in this order:

1. Merge `vendor/main` TAG/SHA - done or pending
2. Resolve shared hotspot per `OWNED.md` - done or pending (name the files)
3. Rebase onto `origin/dev` - `MERGEABLE` or `not a descendant of origin/dev` with recovery `git merge origin/dev` and re-push
4. CI `ci` / `enforce-target` / `hygiene` - each with `pass` / `fail` and the
exact code (`new_suppression`, `unsponsored_surface`, shard name) when failing

When all gates are `MERGEABLE` and hygiene is green, flip Draft -> Ready for
review and post `Ready for human merge - do not squash/rebase.` Stop.

Cursor is the first coordinator, not the only supported integration. The
registry accepts comma-separated IDs and can run multiple coordinators, for
example `FORK_SYNC_COORDINATORS=cursor-webhook,http`.
Expand Down
18 changes: 15 additions & 3 deletions .cursor/skills/opencodex-fork-sync/automation-prompt.md
Original file line number Diff line number Diff line change
Expand Up @@ -29,11 +29,23 @@ Execute only the unresolved handoff stages:
commands.
7. Push the sync branch as needed and open or update a draft PR into `dev`.
Fill Summary, Verification, and Checklist from the PR template. Include the
decision table and the tag SHA. Run
decision table and the tag SHA. Inside the PR body, maintain a sticky
section between `<!-- cursor-sync-progress:start -->` and
`<!-- cursor-sync-progress:end -->` with the 4-line checklist:
(1) Merge `vendor/main` TAG/SHA, (2) Resolve shared hotspot per
`OWNED.md`, (3) Rebase onto `origin/dev` (`MERGEABLE` or
`not a descendant` + `git merge origin/dev`), (4) CI
`ci`/`enforce-target`/`hygiene` with exact failing codes. Mirror the same
checklist in exactly one sticky comment marked
`<!-- cursor-sync-progress -->` - update it in place after every push,
never create a new one. Run
`gh pr view <number> --json mergeable -q .mergeable` and do not stop or ping
the human until it reports `MERGEABLE`.
8. Stop. The human performs the merge commit, never squash or rebase. Do not
merge the PR, close issues, change repository settings, or force-push
8. Until `MERGEABLE` and hygiene green, stay and supervise. After every push, poll `gh pr view <number> --json mergeable` and `gh pr checks` every 60s for 10m. If `not a descendant of origin/dev`, run `git fetch origin dev && git merge --no-edit origin/dev && git push` yourself. For `macos-launchd` timeout-only flakes, run `gh run rerun --failed` once. Update the sticky PR-body section and the single `<!-- cursor-sync-progress -->` comment in place (never a new comment) with the 4-line checklist and exact failing codes. Only `new_suppression` / `unsponsored_surface` need `suppression-approved` / `maintainer-sponsored` human waive - report the blocker but do not auto-waive.
9. When all gates are `MERGEABLE` and hygiene green, flip Draft -> Ready
for review and post `Ready for human merge - do not squash/rebase.` Stop.
The human performs the merge commit, never squash or rebase. Do not merge
the PR, close issues, change repository settings, or force-push
`main`/`origin/main`.

If histories diverge again, use the disconnected `run/dev` rebuild only as an
Expand Down
55 changes: 55 additions & 0 deletions .github/scripts/agent-maintenance.cjs
Original file line number Diff line number Diff line change
Expand Up @@ -195,6 +195,45 @@ function maintenanceReadyEvidence({
};
}

function autonomousMergeEvidence({
pr,
checkRuns = [],
headCommit,
expectedJulesUserId,
authorizedSessionId,
sessionId,
expectedBugbotAppId,
expectedChecksAppId = 15368,
requiredNames = ["ci", "enforce-target", "hygiene"],
labels = (pr?.labels || []),
}) {
const names = new Set(labels.map((label) => typeof label === "string" ? label : label?.name));
const headSha = pr?.head?.sha;
const julesId = Number(expectedJulesUserId);
const sessionKey = (value) => String(value ?? "").replace(/^sessions\//, "");
const authorized = authorizedSessionId && sessionKey(sessionId) === sessionKey(authorizedSessionId);
const prByJules = Number.isSafeInteger(julesId) && julesId > 0 && Number(pr?.user?.id) === julesId;
const authoredByJules = Number.isSafeInteger(julesId) && julesId > 0 &&
[headCommit?.author?.id, headCommit?.committer?.id].some((id) => Number(id) === julesId);
const baselineReady = requiredChecksSuccessful(checkRuns, headSha, requiredNames, expectedChecksAppId);
const bugbotEvidence = exactHeadBugbotEvidence({
checkRuns,
liveHeadSha: headSha,
expectedAppId: expectedBugbotAppId,
});
return {
autonomousLabel: names.has("autonomous-fix"),
baselineReady,
bugbotEvidence,
authorizedSession: Boolean(authorized),
prByJules: Boolean(prByJules),
authoredByJules: Boolean(prByJules && authoredByJules && headCommit?.sha === headSha),
ready: pr?.state === "open" && pr?.base?.ref === "dev" && names.has("autonomous-fix") &&
baselineReady && Boolean(bugbotEvidence) && Boolean(authorized) &&
Boolean(prByJules && authoredByJules && headCommit?.sha === headSha),
};
}

function trustedActiveMaintenanceCount(records) {
return records.filter((record) =>
record?.error ||
Expand Down Expand Up @@ -386,6 +425,19 @@ function createJulesClient({ apiKey, fetchImpl = fetch, sleep = (ms) => new Prom
return assertSession(await request(`/sessions/${encodeURIComponent(id)}`));
}

async function sendMessage(id, prompt) {
if (!/^[^/]+$/.test(id)) throw new Error("invalid Jules session resource id");
if (!prompt || typeof prompt !== "string") throw new Error("sendMessage requires a prompt string");
return request(`/sessions/${encodeURIComponent(id)}:sendMessage`, { method: "POST", body: { prompt }, retryReads: false });
}

async function listSessionActivities(id) {
if (!/^[^/]+$/.test(id)) throw new Error("invalid Jules session resource id");
const result = await request(`/sessions/${encodeURIComponent(id)}/activities`);
if (!result || !Array.isArray(result.activities)) return [];
return result.activities;
}

async function createSessionIdempotently(payload) {
try {
return await createSession(payload);
Expand Down Expand Up @@ -420,6 +472,8 @@ function createJulesClient({ apiKey, fetchImpl = fetch, sleep = (ms) => new Prom
createSession,
createSessionIdempotently,
getSession,
listSessionActivities,
sendMessage,
listSessions,
listSources,
};
Expand All @@ -439,6 +493,7 @@ module.exports = {
exactHeadBugbotEvidence,
generatedSyncBaselineDisposition,
maintenanceReadyEvidence,
autonomousMergeEvidence,
findGithubSource,
hasExactHeadMaintainerWaiver,
isExpectedJulesHeadAdvance,
Expand Down
61 changes: 61 additions & 0 deletions .github/scripts/agent-maintenance.test.cjs
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ const {
exactHeadBugbotEvidence,
generatedSyncBaselineDisposition,
maintenanceReadyEvidence,
autonomousMergeEvidence,
findGithubSource,
hasExactHeadMaintainerWaiver,
isExpectedJulesHeadAdvance,
Expand Down Expand Up @@ -196,6 +197,66 @@ describe("maintenance PR readiness", () => {
});
});

describe("autonomous merge evidence", () => {
const pr = {
number: 42,
state: "open",
base: { ref: "dev" },
user: { id: 77 },
head: { sha: SHA },
labels: [{ name: "autonomous-fix" }],
};
const checks = [
...["ci", "enforce-target", "hygiene"].map((name, id) => ({
id: id + 1, name, app: { id: 15368 }, head_sha: SHA,
status: "completed", conclusion: "success",
})),
{ id: 4, name: "Cursor Bugbot", app: { id: 99 }, head_sha: SHA,
status: "completed", conclusion: "success" },
];
const valid = {
pr,
checkRuns: checks,
headCommit: { sha: SHA, author: { id: 77 }, committer: { id: 77 } },
expectedJulesUserId: 77,
expectedBugbotAppId: 99,
authorizedSessionId: "sessions/abc",
sessionId: "sessions/abc",
};

it("accepts a labeled exact-head Jules fix with all required checks", () => {
const result = autonomousMergeEvidence(valid);
assert.equal(result.ready, true);
assert.equal(result.bugbotEvidence.checkRunId, 4);
});

it("rejects a waiver or missing autonomous-fix label", () => {
assert.equal(autonomousMergeEvidence({
...valid,
checkRuns: checks.slice(0, 3),
labels: ["review-bot-waived"],
reviews: [
{ id: 1, user: { login: "alice" }, commit_id: SHA, state: "APPROVED" },
{ id: 2, user: { login: "carol" }, commit_id: SHA, state: "APPROVED" },
],
maintainers: ["alice", "carol"],
}).ready, false);
assert.equal(autonomousMergeEvidence({ ...valid, pr: { ...pr, labels: [] } }).ready, false);
});

it("rejects stale checks, unauthorized session, and non-Jules head authorship", () => {
assert.equal(autonomousMergeEvidence({ ...valid, sessionId: "sessions/other" }).ready, false);
assert.equal(autonomousMergeEvidence({
...valid,
headCommit: { ...valid.headCommit, sha: "b".repeat(40) },
}).ready, false);
assert.equal(autonomousMergeEvidence({
...valid,
checkRuns: checks.map(check => check.name === "ci" ? { ...check, conclusion: "failure" } : check),
}).ready, false);
});
});

describe("controller fail-closed helpers", () => {
it("uses the latest labeled or unlabeled event for an active dispatch label", () => {
const events = [
Expand Down
Loading
Loading